Topic
Networking
71 guides across the knowledge base.
Network Problems
The controller as a network device: addressing, duplicate addresses, link speed and duplex, connection limits, packet rate and storms, multicast for remote I/O, ring protocols, and time synchronization, with the diagnostics that show which is wrong.
8 min readUpdated Sep 5, 2026
EtherNet/IP
How EtherNet/IP moves control data: CIP over standard Ethernet, implicit I/O connections on a requested packet interval, explicit messaging, producer and consumer tags, and what the network has to provide.
9 min readUpdated Sep 5, 2026
OPC UA
What OPC UA is for, how its information model, security, and transports differ from OPC Classic, where it belongs in a plant, and what to check before relying on it.
8 min readUpdated Sep 5, 2026
Serial Communications
RS-232, RS-422, and RS-485 in practice: which is which, cable and distance, termination, biasing, the common reference wire everyone leaves off, and the settings that have to match at both ends.
9 min readUpdated Sep 5, 2026
Protocol Gateways
Protocol converters between a controller and devices that do not speak its language: what a gateway does, the common pairings in water and wastewater, the mapping table that is the whole configuration, the failure modes a gateway adds, and when to use a native interface instead.
9 min readUpdated Sep 5, 2026
SCADA Architecture
The parts of a SCADA system and how data moves between them: I/O servers, the tag database, clients, the historian, the alarm server, and the topologies from a single panel PC to a redundant, distributed plant.
9 min readUpdated Sep 5, 2026
SCADA Redundancy
What redundant SCADA servers protect against and what they do not, how failover works for tags, alarms, history, and clients, the network and controller layers beneath it, and why an untested failover is not redundancy.
8 min readUpdated Sep 5, 2026
Historian Architecture
How process history is collected, stored, and served: the collector, the archive, and the client layers, where the historian sits relative to SCADA and the DMZ, single-server and tiered designs for a utility, the store-and-forward buffer that survives outages, and the sizing that decides how many years fit on a disk.
9 min readUpdated Sep 5, 2026
SCADA Servers
What the servers in a SCADA system do and what a utility should expect of them: the I/O, alarm, historian, and client roles, physical versus virtual, redundancy, sizing, placement, backup, patching, licensing, and monitoring.
10 min readUpdated Sep 5, 2026
SCADA Communications
How SCADA servers talk to controllers and the field: polling and report by exception, the protocols and what each is for, media from plant Ethernet to radio and cellular, poll rate arithmetic, timeouts and quality, time sync, store and forward, and security.
11 min readUpdated Sep 5, 2026
Lost Communications
What should happen when SCADA loses a device, a site, or everything, how the pattern tells which, the diagnostic order from the server outward through network, firewall, medium, and site, and the design that makes a lost link an alarm rather than an incident.
9 min readUpdated Sep 5, 2026
Client Problems
Diagnosing the operator station rather than the system: a client that will not connect, shows nothing, runs slowly, freezes, or stays silent on an alarm, with the causes, the order of checks, and the standard build and spare that make the fix a swap.
8 min readUpdated Sep 5, 2026
Time Synchronization
Why every clock in a control system must agree and what happens when they do not: out-of-order events, historian gaps at daylight saving, authentication failures, wrong totals. The time source and hierarchy, how each device is synchronized, and the checks.
9 min readUpdated Sep 5, 2026
Ignition
Field notes on Ignition from Inductive Automation: gateway and modules, unlimited licensing per server, Perspective and Vision clients, the SQL-based historian, Python scripting, redundancy, Edge for small sites, and what to decide before building on it.
8 min readUpdated Sep 5, 2026
Network Switches
Selecting and installing the Ethernet switch in a control panel: managed against unmanaged, industrial ratings and DIN rail mounting, ports and media including fiber, ring protocols, power and grounding, and the configuration documented with the panel.
8 min readUpdated Sep 5, 2026
Panel Networking
The network inside a controller panel: which networks exist and how they are kept apart, where the switch sits, copper patching and fiber entry, the radio or cellular router as a panel component, cable management, shield grounding, and labeling.
7 min readUpdated Sep 5, 2026
Zones and Conduits
The IEC 62443 way to segment a control system: grouping assets into zones with a shared security level, inventorying every conduit between them, and turning the drawing into firewall rules. With a worked water utility example.
12 min readUpdated Sep 5, 2026
Vendor Remote Access
Integrators and equipment vendors need to get in. How to let them without leaving a permanent door open: utility-controlled sessions, named accounts, MFA, a jump host, session recording, and what to do about the modem you did not know was there.
11 min readUpdated Sep 5, 2026
Industrial DMZ Design
The buffer zone between the business network and the control system: what goes in it, the no-direct-path rule, push-not-pull data flows, the firewall pair, and the services a utility actually needs to place there.
10 min readUpdated Sep 5, 2026
Jump Hosts
The one machine every remote session must pass through: what a jump host is, how it is hardened, what it may reach, session recording, the tools it carries, and why a vendor laptop never gets past it.
9 min readUpdated Sep 5, 2026
Default Credentials
The passwords printed in the manual: where they hide in a control system, why they are the first thing an attacker tries, how to find every one on site, and the procedure for changing them without locking yourself out.
8 min readUpdated Sep 5, 2026
Industrial Firewalls
Firewalls built for control networks: how they differ from office firewalls, where they belong in a utility network, transparent versus routed modes, Modbus and DNP3 awareness, logging, and the ruggedized units that protect one controller or a remote site.
9 min readUpdated Sep 5, 2026
Firewall Rule Design
Writing the rule set for a control network boundary: default deny, one rule per conduit with its reason, hosts not subnets, protocol and port and function, direction and initiator, logging on every rule, and the review that removes forgotten rules.
9 min readUpdated Sep 5, 2026
Historian Security
The historian is the most connected server in a control system and the most exposed: giving the office, reports, and the cloud the data they need without a path to the plant, with a collector in the control zone, a replica in the DMZ, and one-way flow.
9 min readUpdated Sep 5, 2026
Isolating a Compromised System
Cutting a compromised machine, segment, or site off from the control system without stopping the process: who may decide, isolation points planned in advance, disconnecting the network rather than the power, running on manual control, and preserving evidence.
9 min readUpdated Sep 5, 2026
Building an OT Asset Inventory
The list of everything in the control system with a network interface or a program, and how to build one that is right: what counts, the fields to record, the site walk, the switch tables and passive listening that find the rest, and keeping it current.
9 min readUpdated Sep 5, 2026
Passive Discovery
Finding out what is on a control network by listening rather than probing: why active scans are risky around older controllers, how a mirror port feeds a sensor, what the traffic reveals, the blind spots, and how the sensor becomes continuous monitoring.
8 min readUpdated Sep 5, 2026
Documenting Firmware Versions
Why the firmware version of every controller, module, drive, switch, radio, and instrument belongs in the inventory with the date it was read: advisories are issued by version. Where to read each one, the several versions one controller has, and the cadence.
8 min readUpdated Sep 5, 2026
Compensating Controls
What to do about a vulnerability that cannot be patched now or ever: restricting who can reach it, disabling the service, blocking dangerous protocol functions, allowlisting, monitoring, physical and procedural controls, matched to the attack path.
8 min readUpdated Sep 5, 2026
VLAN Segmentation
Using VLANs to build the zones of a control network on shared switches: what a VLAN separates and what it does not, the zone-to-VLAN mapping, trunks and the native VLAN, routing only through a firewall, and where separate hardware begins.
9 min readUpdated Sep 5, 2026
Data Diodes
Hardware that lets data flow one way only, from the control network outward, with no physical return path: what a data diode and a unidirectional gateway are, where they belong, what they can and cannot carry, and when a firewall is enough instead.
8 min readUpdated Sep 5, 2026
Segmenting a Remote Site
A lift station, a well, or a tank site as its own zone: the site firewall and what it permits, the modem as transport with no public address, cameras and extras off the control segment, engineering access through the plant, and local control without the link.
9 min readUpdated Sep 5, 2026
VPN Design
How a VPN fits remote access for a control system: it terminates in the DMZ and lands on a jump host, never the control network; site-to-site tunnels carry telemetry; user tunnels require multi-factor and individual accounts; the concentrator is patched fast.
9 min readUpdated Sep 5, 2026
Deep Packet Inspection
What a firewall can do when it understands the control protocols: allowing reads and blocking writes, permitting programming only from one workstation in a window, rejecting malformed messages, and alerting on function codes that should never appear.
8 min readUpdated Sep 5, 2026
Firewall Logging and Review
Making the firewall log useful: logging on every rule including sensitive permits, sending logs to a collector off the firewall, what denials and unexpected permits mean, a weekly review a small utility can sustain, and the alerts worth waking someone for.
8 min readUpdated Sep 5, 2026
Firmware Management
Updating the firmware of controllers, modules, drives, HMIs, switches, and radios without breaking the plant: why firmware lags and why it still matters, tracking versions, deciding what to update and when, and the update as a planned outage with a rollback.
9 min readUpdated Sep 5, 2026
Disabling Unused Services
Every service a device runs is a way in, and most ship with more running than the plant uses: web servers, file transfer, shells, discovery, management protocols, unused ports. Finding what is listening, deciding what the plant needs, and turning off the rest.
8 min readUpdated Sep 5, 2026
How to Assign IP Addresses on a Control Network
Build an addressing plan before the first device is configured: one subnet per zone and site, a fixed block layout so an address says what the device is, static addresses on everything that controls a process, and a schedule that is kept current.
9 min readUpdated Sep 5, 2026
How to Configure VLANs on a Control Network
Turn a zone plan into switch configuration: a VLAN per zone with its own subnet, access ports for devices, tagged trunks between switches, a native VLAN that carries nothing, a separate management VLAN, and routing between VLANs only through the firewall.
10 min readUpdated Sep 5, 2026
How to Troubleshoot an Ethernet Connection
Work an Ethernet problem one layer at a time: link light and cable, then speed, duplex, and VLAN on the switch port, then address, mask, and gateway, then the application port through the firewall. Each layer has a one-minute test that rules it in or out.
10 min readUpdated Sep 5, 2026
How to Diagnose Packet Loss
Find where and why frames are dropped: measure loss with a continuous ping, localize it hop by hop from both directions, read the port counters on the path, and match the pattern to its cause: a cable, a duplex mismatch, congestion, a loop, or a radio link.
10 min readUpdated Sep 5, 2026
How to Configure Remote I/O
Add a remote I/O rack to a controller over Ethernet: plan the network and addresses, set the adapter, and prove every point and the failure behavior before the rack goes into service.
8 min readUpdated Sep 5, 2026
How to Configure Remote Access
Give operators and engineers a way into the SCADA system from outside that does not give it to anyone else: a virtual private network with multi-factor authentication terminating in a demilitarized zone, and a test that proves the path works and that the.
8 min readUpdated Sep 5, 2026
How to Test Fiber
Test a fiber link at acceptance and at fault: inspect and clean every connector, measure end-to-end loss with a light source and power meter in both directions and at the operating wavelengths, and record everything with the fiber schedule.
8 min readUpdated Sep 5, 2026
Device Times Out
A polled device that answers late or not at all: how to read the driver counters, tell a dead device from a slow one, and find the timeout setting, the bus loading, the radio latency, the duplicate address, or the device that is simply too busy to answer.
9 min readUpdated Sep 5, 2026
Intermittent Radio Path
A site that drops and returns by the hour, season, or weather: thin fade margin, foliage, a new obstruction, a loosened antenna, coax taking water, a corroding connector, interference, or a marginal supply. How to trend signal against time and weather.
8 min readUpdated Sep 5, 2026
Cellular Modem Will Not Register
A modem that never attaches to the network: a module not activated, provisioned, or suspended; unsupported bands or a network shutdown; no antenna or coverage; a wrong access point name; or a reset modem. Reading the registration state and asking the carrier.
8 min readUpdated Sep 5, 2026
Frequent Reconnects
A cellular site that connects, drops, and reconnects: a weak signal at the cell edge, tower handoffs, idle session teardown, a NAT timeout that needs a keepalive, a firmware fault, a sagging supply, or an antenna problem. Settings that keep sessions up.
8 min readUpdated Sep 5, 2026
Data Plan or APN Problems
A modem that registers but has no data, or runs out mid-month: a wrong or changed APN, a capped or throttled plan, a module on the wrong plan or network, a missing static address, or polling that uses more data than planned. Sizing a plan, cutting traffic.
8 min readUpdated Sep 5, 2026
VPN Tunnel Drops
The modem is up and the tunnel keeps dropping: a changing cellular address, keepalive longer than the carrier timeout, mismatched rekey lifetimes, an oversized MTU, a modem reconnecting under the tunnel, a full concentrator, or a clock or certificate fault.
9 min readUpdated Sep 5, 2026
Weak Cellular Signal
A modem at the edge of coverage: the signal readings that matter, an antenna inside a metal enclosure or vault, the wrong band, a damaged antenna or lossy coax, a tower or carrier change, and fixes from a mast antenna to a directional one or a new medium.
8 min readUpdated Sep 5, 2026
Fiber Link Down
A fiber link with no light: a cut or crushed cable, a failed or unseated transceiver, a reversed patch cord, a dirty connector, a disabled port, a mismatched module pair, or a dead media converter. Reading port state and optical power to find the break.
8 min readUpdated Sep 5, 2026
High Optical Loss
A link that is up but running near the receiver floor: the loss budget from transmitter to receiver and what ate it. Dirty connectors, bad splices, tight bends, a run too long for the module, or a wrong fiber type. Measuring the loss and getting margin back.
9 min readUpdated Sep 5, 2026
Intermittent Fiber Link
A fiber link that flaps: down for seconds and back, worse at night, in the cold, in wind, or when a door opens. No margin, a nearly seated connector, a failing or hot transceiver, a moving bend, water freezing in a splice case, or a port flapping on its own.
8 min readUpdated Sep 5, 2026
Wrong Fiber Type or Wavelength
A link that will not come up, or runs with high loss, because parts do not match: single-mode modules on multimode fiber, a multimode cord in a single-mode run, mixed grades, different wavelengths, or a same-wavelength bidirectional pair. Reading the markings.
8 min readUpdated Sep 5, 2026
Dirty or Damaged Connector
The most common fiber fault: a connector end face with dust, oil, or a scratch that takes decibels from the link and damages its mate. How to inspect with a scope, what contamination and damage look like, how to clean properly, and when to replace it.
8 min readUpdated Sep 5, 2026
Intermittent Packet Loss
Polls that occasionally fail, tags that flicker bad, a ping that drops one in fifty: a bad cable or port, a duplex mismatch, a saturated link, a buffer overrun, a marginal radio or fiber hop, a slow device, or a loop. Finding which hop loses packets and why.
9 min readUpdated Sep 5, 2026
Cannot Ping Across VLANs
Two devices that work on their own networks but cannot reach each other across a VLAN boundary: no route, a wrong or missing gateway, a mask that puts the target on the wrong side, a trunk missing the VLAN, or a firewall rule. Testing each in order.
8 min readUpdated Sep 5, 2026
Duplicate IP Address
Two devices claiming one address: a controller that answers sometimes, a workstation that reports a conflict, a ping returning from two hardware addresses. Where duplicates come from, finding both in the switch address table, and the discipline that stops it.
7 min readUpdated Sep 5, 2026
Switch Port Errors Incrementing
What each counter on a managed switch port means and which fault makes it grow: check errors from a damaged cable or noise, late collisions from a duplex mismatch, runts from a bad transceiver, discards from congestion, link flaps from a marginal connection.
9 min readUpdated Sep 5, 2026
Broadcast Storm
A network suddenly slow or dead everywhere, every link light solid: a loop between switches without protection, a failed ring protocol, or a device flooding broadcasts. Recognising a storm, breaking it with a cable pull, finding the loop, and preventing it.
8 min readUpdated Sep 5, 2026
Client Cannot Connect
A workstation, web, or mobile client that cannot reach the SCADA server: the service down, a firewall path closed, a license or session limit, a certificate or name failure, a version mismatch after an update, or expired credentials. Testing each layer.
8 min readUpdated Sep 5, 2026
Network Drawings
The two drawings every control network needs: a logical drawing of zones, subnets, VLANs, firewalls, and conduits, and a physical drawing of switches, ports, cables, fiber, radios, and sites. What each shows and why they are sensitive.
9 min readUpdated Sep 5, 2026
Fiber Schedules
The record of every fiber strand between every pair of patch panels: cable identifiers, strand numbers and the standard color sequence, fiber type, connectors, what each strand carries, splices, lengths, and test results, with the labeling that matches it.
8 min readUpdated Sep 5, 2026
Network Schedules
The tables behind the network drawings: the address schedule of every device, the switch port schedule of every port, the VLAN table, and the conduit list of what the firewalls permit. How they are built, kept as the single source of truth, and protected.
8 min readUpdated Sep 5, 2026
Fiber Between Buildings, Every Time
The copper Ethernet cable between two buildings works on the day it is pulled and costs the plant a controller, a switch, and how to specify it so it stays simple.
7 min readUpdated Sep 5, 2026
The Cellular Router Is the Front Door
The most common way into a small utility control system is not a sophisticated attack on the plant firewall. It is a cellular router at a lift station with a public address and the password it shipped with. How these get installed, and the short list of.
8 min readUpdated Sep 5, 2026
One Flat Network Is One Big Fault Domain
A looped patch cable in an office closet took down every PLC at the plant, because the office and the plant were one network. Why a flat network makes every fault a plant-wide fault, and how to get there one switch at a time.
9 min readUpdated Sep 5, 2026
The Vendor Laptop Is on Your Network Now
Every service call ends with a laptop plugged into the control network, and most utilities have no rule about it. What can go wrong when a vendor connects, and how to have the conversation without losing the vendor.
9 min readUpdated Sep 5, 2026
The Purdue Model
The reference architecture most segmentation designs still start from: what each level contains, where the DMZ goes, and how it maps to a water utility.
8 min readUpdated Aug 20, 2026
Ethernet Device Drops Offline
An industrial Ethernet device that disappears and comes back. Duplex mismatch, cabling, spanning tree, and the switch counters that identify it in minutes.
9 min readUpdated Aug 16, 2026
Other topics
Direct contact
Have a controls question?
Reach Eric Sullivan directly about anything on this site, a controls or automation topic, or one of his personal projects.